{"id":"CVE-2026-64649","aliases":["GHSA-89xv-2m56-2m9x"],"title":"Next.js: Server-Side Request Forgery in Server Actions on custom servers","summary":"Next.js: Server-Side Request Forgery in Server Actions on custom servers","severity":"high","cwe":["CWE-918"],"vendor":"next","product":"next","ecosystem":"npm","affected":["next >= 14.1.1, < 15.5.21","next >= 16.0.0, < 16.2.11"],"patched":["next 15.5.21","next 16.2.11"],"published":"2026-07-22","updated":"2026-07-22","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-89xv-2m56-2m9x","references":[{"url":"https://github.com/vercel/next.js/security/advisories/GHSA-89xv-2m56-2m9x"},{"url":"https://github.com/vercel/next.js/commit/b51206321854193208c0805ba42acc49287f942b"},{"url":"https://github.com/vercel/next.js/commit/e3e5666ccead3a15162793d697af5e48b7cc0498"},{"url":"https://github.com/vercel/next.js/releases/tag/v15.5.21"},{"url":"https://github.com/vercel/next.js/releases/tag/v16.2.11"},{"url":"https://github.com/advisories/GHSA-89xv-2m56-2m9x"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-23T00:08:38.900Z","epss":0.00872,"epssPercentile":0.57332,"slug":"CVE-2026-64649","body":"## Overview\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs on custom servers, or on deployments not behind a proxy that pins the host. Managed hosting pins the host upstream and is not affected; `next start` and standalone output do the same from version 14.2 onward.\n\n## Workarounds\n\nIf you cannot upgrade, ensure clients do not control the host header your application receives. Pin or validate `Host` and `X-Forwarded-Host` at your edge or proxy. On version 14.2.0 and later, you can additionally set the `__NEXT_PRIVATE_ORIGIN` environment variable to your deployment's real origin:\n\n```bash\n__NEXT_PRIVATE_ORIGIN=https://www.example.com node server.js\n\n## Affected packages\n\n- `next >= 14.1.1, < 15.5.21`\n- `next >= 16.0.0, < 16.2.11`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `next 15.5.21`\n- `next 16.2.11`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}